What problem does it solve?
During authorized security assessments, exposed version control metadata, backup files, and configuration artifacts can leak sensitive data including source code, credentials, and internal infrastructure details, which is time-consuming and error-prone to manually detect across all common paths and version control system types.
Core Features & Use Cases
- Multi-VCS Exposure Detection: Identifies exposed .git, .svn, .hg, and .bzr metadata across common web-accessible paths.
- Backup & Config Leak Scanning: Probes for common backup archives, .env files, and misconfigured server artifacts that may contain sensitive data.
- Guided Recovery Workflows: Provides step-by-step instructions and open source tool recommendations to safely extract exposed data during authorized assessments.
Use Case: For example, during a web application penetration test, use this skill to quickly check for exposed .git directories and .env files that could reveal database credentials or proprietary source code.
Quick Start
Use the insecure-source-code-management skill to scan the target web application for exposed version control metadata, backup files, and configuration leaks during your authorized security assessment.